Fake $TSLA Stock Pre-sale Uses Wallet Screening to Identify Victims and Drain Funds

cryptonews.ruPublished on 2026-08-12Last updated on 2026-08-12

Abstract

Cybercriminals are selling a $500 "Tesla token pre-sale" scam kit that allows even non-technical users to set up fake investment websites. The kit, sold by a user named xrep, includes hosting, phishing pages, and a fake dashboard. The scam impersonates Tesla, targeting social media users with fake exclusivity offers. It employs tactics like fake countdown timers and urgency to create FOMO (fear of missing out). Victims are lured to connect their wallets for a "bonus" and are then tricked into providing their 12-word recovery phrase, leading to complete wallet drainage. An alternative method directly requests cryptocurrency transfers to scammer-controlled addresses. The operator's dashboard tracks victim activity, location, and stolen recovery phrases, allowing the scammer to check a wallet's value before draining it and to artificially inflate fake balances to solicit more payments. This scheme follows recent warnings from the U.S. IRS about fake crypto tax portals and other phishing attacks targeting hardware wallet users.

A ready-made kit for fraud is being sold for $500 on a cybercriminal forum. Anyone with almost no technical skills can set up a fake $TSLA token pre-sale and drain the wallets of anyone who invests.

Hacker Sells Scam as a Ready-Made Product

This tool kit was developed by a forum user with the handle xrep, who has been active in the cybercriminal underground since March 2026. It has received positive feedback from other criminals.

Researchers stated that this product is a "complete scam in a box." The kit includes hosting, phishing pages, a fake investment dashboard, and tools for trac victims.

Cybersecurity specialists from Malwarebytes discovered the fraudulent scheme on May 16. It displays a pre-sale page with the Tesla name and logo, presented as an exclusive early purchase opportunity for X users. The website operates in multiple languages and works on both phones and computers.

At the start of the attack, an X user is asked to pass an "eligibility check." The page then displays that user's real profile picture to create the impression that the offer was selected for them.

The scam creates a sense of FOMO (fear of missing out) using a progress bar that starts filling, a countdown timer, and warnings about an imminent price increase.

The first investment option offers a 15% bonus for connecting a wallet. Then the form requests the 12-word recovery phrase to completely drain the cryptocurrency wallets.

Another "investment" option bypasses the wallet and asks the victim to send Bitcoin, Ethereum, USDT, or Dogecoin to an address controlled by the operator. In the end, the buyer sees a fake balance on their account.

Screenshot showing the fake Tesla scam website. Source: Malwarebytes.

Fraud Kit Steals Location and Recovery Phrases

The dashboard makes the kit more dangerous. It allows the operator to see how victims navigate the site, log usernames and locations, and collect recovery phrases entered on the phishing page. The operator can check if a wallet contains anything valuable to steal before attempting to take it over.

It can also artificially inflate the balance on request, making the user believe their investment is paying off and pay even more. If the user has already paid, the dashboard sends a message demanding an additional network fee.

On August 3rd, the U.S. Internal Revenue Service warned that scammers are sending letters to cryptocurrency owners, directing them to a fake "Digital Asset Compliance Portal" that looks like IRS[.]gov, aiming to steal wallet login creddentials. According to the agency, such a portal does not exist.

In May, Cryptopolitan reported that scammers were sending printed letters to Ledger owners. These letters described a fake "Quantum Resistance Security Update" that used QR codes to phish for 24-word recovery phrases.

end-content

Related Questions

QWhat is the key functionality of the fake Tesla stock pre-sale scam toolkit described in the article?

AThe toolkit is a 'full scam in a box' that includes hosting, phishing pages, a fake investment dashboard, and victim-tracking tools. It allows scammers to conduct fake Tesla ($TSLA) token pre-sales and trick users into providing wallet recovery phrases or sending cryptocurrency to attacker-controlled addresses.

QHow does the scam website create a sense of urgency or FOMO (Fear of Missing Out) for potential victims?

AIt uses a combination of visual elements like a filling progress bar, a countdown timer, and warnings about an imminent price increase to create the impression of scarcity and urgency, pressuring users to act quickly.

QWhat personal and financial information does the scam's control panel allow the operator to collect from victims?

AThe control panel allows the operator to see how victims navigate the site, register usernames and locations, and collect the wallet recovery phrases entered on the phishing page. It also lets the operator check if a wallet holds anything valuable before attempting to steal from it.

QAccording to the article, how much does the pre-made scam toolkit sell for on the cybercriminal forum?

AThe pre-made scam toolkit is sold for $500 on the cybercriminal forum.

QWhat recent similar phishing warning did the U.S. Internal Revenue Service (IRS) issue, as mentioned in the article?

AOn August 3, the U.S. IRS warned that scammers were sending letters to cryptocurrency owners directing them to a fake 'Digital Asset Compliance Portal' designed to look like IRS[.]gov, with the goal of stealing wallet recovery phrases. The IRS stated that no such portal exists.

Related Reads

Trading

Spot
活动图片